Enumerating & Retrieving Password Policies
Enumerando a política de senha - do Linux - Credentialed
crackmapexec smb 172.16.5.5 -u avazquez -p Password123 --pass-polUsando rpcclient
rpcclient -U "" -N 172.16.5.5querydominfo
getdompwinfo : Obtendo a politica de senha
Usando enum4linux
enum4linux -P 172.16.5.5Usando enum4linux-ng
enum4linux-ng -P 172.16.5.5 -oA ilfreightExibindo o conteúdo de ilfreight.json
cat ilfreight.jsonUsando ldapsearch
ldapsearch -h 172.16.5.5 -x -b "DC=INLANEFREIGHT,DC=LOCAL" -s sub "*" | grep -m 1 -B 10 pwdHistoryLengthEnumerando a política de senha - do Windows
Usando net.exe
net accountsUsando o PowerView
import-module .\PowerView.ps1
Get-DomainPolicyLast updated